CVE Vulnerabilities

CVE-2019-1696

Uncontrolled Resource Consumption

Published: May 03, 2019 | Modified: Nov 26, 2024
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVSS 2.x
3.3 LOW
AV:A/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent or remote attacker to cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.

Weakness

The product does not properly control the allocation and maintenance of a limited resource.

Affected Software

Name Vendor Start Version End Version
Secure_firewall_management_center Cisco 2.9.8 (including) 2.9.8 (including)
Secure_firewall_management_center Cisco 2.9.9 (including) 2.9.9 (including)
Secure_firewall_management_center Cisco 2.9.10 (including) 2.9.10 (including)
Secure_firewall_management_center Cisco 2.9.11 (including) 2.9.11 (including)
Secure_firewall_management_center Cisco 2.9.12 (including) 2.9.12 (including)
Secure_firewall_management_center Cisco 2.9.13 (including) 2.9.13 (including)

Potential Mitigations

  • Mitigation of resource exhaustion attacks requires that the target system either:

  • The first of these solutions is an issue in itself though, since it may allow attackers to prevent the use of the system by a particular valid user. If the attacker impersonates the valid user, they may be able to prevent the user from accessing the server in question.

  • The second solution is simply difficult to effectively institute – and even when properly done, it does not provide a full solution. It simply makes the attack require more resources on the part of the attacker.

References